The Total Economic Impact™ Of Semperis

Business Benefits Enabled By Semperis

A Forrester Total Economic Impact Study Commissioned By Semperis, April 2024

The ever-evolving cybercriminal ecosystem continuously poses new and unique security threats to organizations of all shapes and sizes. Most (84%) organizations experienced an identity-related breach in the last year and, with the average total breach costing $3.5 million, organizations must combat this risk by investing in technology that safeguards hybrid enterprise identity systems with on-premises Active Directory (AD) and Entra ID in the cloud.1 Forrester found that organizations that use Semperis can both recover their AD in the event of a ransomware attack and remediate object- and group-level incidents in AD and Entra ID 90% faster. This translates to millions of dollars in savings and reduces the likelihood of a successful attack.

Semperis protects critical enterprise identity services for security teams charged with defending hybrid AD environments from cyberattacks, data breaches, and operational errors. By offering comprehensive protection for identity environments — including Active Directory, Entra ID, and Okta — Semperis provides a layered defense against identity-based incidents before, during, and after an attack, all supported by an expert, dedicated incident response team.

Semperis commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study and examine the potential benefits and financial impacts enterprises may realize by deploying Semperis.2 

icon

AD disaster recovery

90% faster

icon

Reduction in average likelihood of a successful hybrid AD-related ransomware attack

25% reduction

icon

Object- and group-level recovery

90% faster

icon

Reduction in time spent monitoring the hybrid AD environment

40%

icon

Three-year benefits (PV)

$9.5M

To better understand the benefits and risks associated with this investment, Forrester interviewed six representatives with experience using Semperis. The interviewees’ organizations range in size and geography and are from a variety of industry sectors, including healthcare, financial services, energy, and professional services. For the purposes of this study, Forrester aggregated the interviewees’ experiences and combined the results into a single composite organization that is in a highly regulated industry with sensitive data and has 50,000 employees and revenue of $10 billion per year.

Prior to investing in Semperis, interviewees noted their organizations used a mix of identity threat detection, response, and prevention tools, and used generic enterprise backup and/or traditional AD recovery solutions, such as a bare-metal recovery approach, to back up their data. This, in conjunction with the existing tools’ inefficient manual processes and subsequent business challenges, put interviewees’ organizations at a heightened risk of an AD- and Entra ID-related ransomware attack and AD- and Entra ID-related operational inefficiencies.

After the investment in Semperis, interviewees noted their organizations gained full visibility of their hybrid AD environments and were thus able to efficiently identify and address potential cyberthreats to proactively avoid an identity-based attack. By improving their overall security posture, the interviewees’ organizations reduced the likelihood of an identity-based attack and cut down credential abuse. Interviewees stated that in the event of an AD attack, their organizations achieved faster AD recovery with Semperis’ Active Directory Forest Recovery (ADFR) solution, reducing end-user downtime and reaping significant labor and revenue savings. The interviewees also noted their organizations also saw additional time savings on AD and Entra ID environment monitoring and object- and group-level remediation through the automation capabilities of Semperis’ Directory Services Protector (DSP) solution. Through these improvements, interviewees said their organizations saw added value through improved brand credibility and the ability to maintain a strong security posture as their businesses continued to grow.

Key Findings

Quantified benefits. Three-year, risk-adjusted present value (PV) quantified benefits for the composite organization include:

  • Improved business continuity due to faster hybrid AD attack recovery yielding $3.9 million in savings. Semperis’ Active Directory Forest Recovery (ADFR) tool reduces the composite organization’s AD backup and recovery timeline by 90%. The composite organization also gains the ability to conduct post-breach forensics to close back doors and eliminate persistence. By reducing the recovery timeline and the risk of malware reinfection, the composite limits its revenue and labor losses during downtime, avoiding prolonged business disruption and quickly regaining operational stability by bringing AD back to a trusted state.
  • Improved business continuity through a reduction in the likelihood of a successful hybrid AD attack worth $1.2 million. In addition to the business continuity savings realized through ADFR, the composite organization reaps additional value with Directory Services Protector (DSP). DSP provides full visibility of hybrid AD environments to close existing security gaps by continuously monitoring for security indicators and identifying potential threats before they manifest into a full-on attack. This risk reduction allows the composite to reduce the likelihood of experiencing successful AD and Entra ID attacks by 25%, further cutting its revenue and labor losses. Note that the security benefit of preventative action is difficult to quantify accurately, so the 25% reduction is intentionally a conservative estimate.
  • Object- and group-level remediation savings worth $4.3 million. When unintended changes are made to objects and groups in the hybrid AD environment, the composite organization uses DSP’s granular rollback capabilities to quickly restore normal configurations of individual attributes, group members, objects, and containers — reducing end-user downtime and improving operational resilience. 
  • Hybrid AD environment monitoring efficiencies that save $109,000. The composite organization realizes substantial IT team time savings for AD environment monitoring with DSP in place. Seamless integration into existing security operations center (SOC) environments and real-time alerts and automation features, such as automatic rollback of suspicious changes and continuous security assessments to combat configuration drift, allow the composite’s IT team to spend less time manually investigating potential threats in AD and Entra ID and more time on high-value work.

Unquantified benefits. Benefits that provide value for the composite organization but are not quantified for this study include:

  • Improved brand credibility. The composite organization experiences improved hybrid AD environment resilience and data integrity through its investment in Semperis. By applying Semperis’ AD security expertise and experience in identity attack incident response to achieve a stronger security posture, the composite boosts its reputation among customers and unlocks new avenues for business growth.
  • Improved visibility of the hybrid AD environment. The composite organization gains a comprehensive view of its hybrid AD environment, improving its threat detection abilities and subsequently reducing its AD attack surface area.

The representative interviews and financial analysis found that a composite organization experiences benefits of $9.5 million over three years.

We initially went with Semperis because they are the market leader in the space, but their solution has actually delivered value to our organization. Their patented technology for malware or wiper attack recovery of AD along with our newfound full visibility into our AD environment has delivered great results.”

Technical architect, AD, professional services

Key Statistics

  • icon icon

    AD disaster recovery

    90% faster
  • icon icon

    Reduction in average likelihood of a successful AD-related ransomware attack

    25% reduction
  • icon icon

    Object- and group-level recovery

    90% faster
  • icon icon

    Reduction in time spent monitoring the AD environment

    40%
  • icon icon

    Three-year benefits (PV)

    $9.5M
  • icon icon
  • icon icon
  • icon icon

Benefits (Three-Year)

Improved business continuity due to faster hybrid AD attack recovery Improved business continuity due to a reduction in the likelihood of a successful hybrid attack Object- and group-level remediation savings Hybrid AD environmental monitoring efficiencies

TEI Framework And Methodology

From the information provided in the interviews, Forrester constructed a Total Economic Impact™ framework for those organizations considering an investment in Semperis.

The objective of the framework is to identify benefit, flexibility, and risk factors that affect the investment decision. Forrester took a multistep approach to evaluate the impact that Semperis can have on an organization.

  1. Due Diligence

    Interviewed Semperis stakeholders and Forrester analysts to gather data relative to Semperis.

  2. Interviews

    Interviewed six representatives at five organizations using Semperis to obtain data about benefits and risks.

  3. Composite Organization

    Designed a composite organization based on characteristics of the interviewees’ organizations.

  4. Financial Model Framework

    Constructed a financial model representative of the interviews using the TEI methodology and risk-adjusted the financial model based on issues and concerns of the interviewees.

  5. Case Study

    Employed fundamental elements of TEI in modeling the investment impact: benefits, flexibility, and risks. Given the increasing sophistication of financial analyses related to IT investments, Forrester’s TEI methodology provides a complete picture of the total economic impact of purchase decisions. Please see Appendix A for additional information on the TEI methodology.

Disclosures

Readers should be aware of the following:

This study is commissioned by Semperis and delivered by Forrester Consulting. It is not meant to be used as a competitive analysis.

Forrester makes no assumptions as to the potential benefits that other organizations will receive. Forrester strongly advises that readers use their own estimates within the framework provided in the study to determine the appropriateness of an investment in Semperis.

Semperis reviewed and provided feedback to Forrester, but Forrester maintains editorial control over the study and its findings and does not accept changes to the study that contradict Forrester’s findings or obscure the meaning of the study.

Semperis provided the customer names for the interviews, but Semperis did not participate in the interviews. Only Semperis customers participated in closed-door interviews.

Consulting Team:

Sanitra Desai

Zahra Azzaoui

Cookie Preferences

Accept Cookies

A cookie is a small text file that a website saves on your computer or mobile device when you visit the site. It enables the website to remember your actions (data inputs, website navigation), so you don’t have to re-enter data when you come back to the site or browse from one page to another.

Behavioral information collected by our web analytics vendor is used to analyze data pertaining to visitor trends, plan website enhancements, and measure overall website effectiveness. We may also use cookies or web beacons to help us offer you products, programs, or services that may be of interest to you and to deliver relevant advertising. We may use third-party advertising companies to help tailor website content to users or to serve ads on our behalf. These companies may also employ cookies and web beacons to measure advertising effectiveness.

Please accept cookies and the collection of behavioral information to receive full functionality and enhance your experience. If you decline cookies, some features of the website may not function normally.

Please see our Privacy Policy for more information.